markdowneditor

Data Protection Impact Assessment (DPIA)

Data protection impact assessment

ISO & ComplianceStandarddpia

How to use: Trigger check first: profiling, large-scale sensitive data, or new tech usually means required. DPO consultation is mandatory for high residual risk.

Preview

Data Protection Impact Assessment (DPIA)

ISO/IEC 27701 + GDPR Art.35 required for high-risk processing. Required when: systematic profiling, large-scale sensitive data, public-area monitoring, new tech, or processing could restrict data subject rights.

FieldValue
Assessment IDDPIA-YYYY-NNN
Processing activityname
Assessor@name
DPO consulted@name – required for high-risk
DateYYYY-MM-DD
StatusAssessment / mitigation / approved

1. Processing description

  • What: personal data types, subjects (customers/employees/users)
  • Purpose: why processing happens
  • Scale: volume, duration, geographic scope
  • Tech: systems, storage, transfers
  • Data flow: collection → use → storage → sharing → deletion

2. Necessity & proportionality

  • Is the processing necessary for the purpose?
  • Is there a less invasive alternative?
  • Lawful basis: consent / contract / legal obligation / legitimate interest

3. Risk assessment to data subjects

Risk to individualsLikelihoodSeverityExisting controlsResidual
Unauthorized disclosureH/M/LH/M/Lencryption, access
Re-identification of anonymized
Discrimination/profiling harm
Loss of availability

4. Consultation

  • DPO opinion: summary of advice given
  • Data subject input: how views were considered (if required)

5. Mitigation plan

RiskMeasureOwnerResidual targetDue
High residual riskadditional control@nameacceptable

6. Outcome

  • Processing may proceed (residual acceptable)
  • Proceed with mitigations above
  • Requires prior consultation with supervisory authority
  • Must not proceed

7. Approvals

RoleNameDecisionDate
DPOapproved/conditions
Data controller

Related templates